forumNew topic

They're trying to sell us a SOC security monitoring service, is it really necessary for our size?

PPınar Ç***Expert
Job title
Call center representative
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
189
#1

We are a 20-person team working in B2B software and logistics integration. We don't have a massive IT infrastructure, just 3 cloud servers and laptops used by our employees. Last week, a cybersecurity firm called and told us we need an outsourced corporate SOC, basically a 24/7 security monitoring service, for our company. They quoted around 45,000 TL per month for the package.

Our entire current cloud and IT infrastructure budget is around 30,000 TL a month, so committing 1.5 times that just for security monitoring really makes me pause. The sales rep claims that logs will be monitored continuously via AI and we'll be notified immediately in suspicious cases. But when an alert drops at 3 AM, we don't have an on-call systems engineer to intervene; so even if an alert comes in, I honestly don't know what good it would do.

Is this kind of SOC security monitoring service truly essential for a small company with 20 employees? Or is there a more reasonable middle-ground solution to protect our core systems and employee workstations without taking on this cost?

GGürkan V***Member
Job title
Customer service representative
Sector
Printing
Organization type
workshop
Joined
Aug 2023
Message
118
Most Helpful#2

Short answer: For a 20-person business, a 24/7 outsourced SOC service is usually an unnecessary operational burden. Unless you have regulatory obligations or a critical database carrying direct high financial risk, properly configuring basic security layers is far more rational than paying 45,000 TL a month.

SOC centers aggregate and correlate activity logs across your systems to detect anomalies. But monitoring is only half the battle. When a critical alert hits at midnight, an authorized specialist on your end needs to access the systems and take action. If your company lacks overnight on-call staff or incident responders, the provider merely generates an alert email that you'll end up reading in the morning.

For an organization of your scale, following these steps is far healthier to minimize risk while protecting your budget: 1) Deploy a centralized, cloud-based endpoint protection solution for servers and all user laptops with automatic quarantine rules enabled, 2) Enforce multi-factor authentication (MFA) across email, cloud server management panels, and all internal accounts, 3) Take daily cloud server backups to a separate, immutable storage location isolated from the primary system, 4) Use monitoring plugins for critical servers that trigger basic threshold alerts during business hours.

These foundational measures will bring your monthly expenditure down to a fifth of the quoted price while already neutralizing the vast majority of attack vectors you face.

AAli T***Member
Job title
Call center representative
Sector
Paper
Organization type
workshop
Joined
Jul 2024
Message
269
#3

Don't confuse endpoint protection with a SOC. A SOC parses logs and employs analysts. In setups with 20 devices like yours, the volume of meaningful logs to analyze daily is already very low. Just install modern endpoint software with automated blocking and quarantine capabilities, don't pour money into analysts every month.

KKoray B***ExpertCommunity member
Joined
Jan 2023
Message
235
#4

We're a 35-person company; last year we bought into similar promises and signed a contract for 35,000 TL a month. In 6 months they generated 42 alerts total. 40 were false alarms, and the remaining 2 were our own developer entering the wrong password while testing a VPN. We saw zero benefit and walked away when the contract ended.

EEfe A***Member
Job title
System support specialist
Sector
Software
Organization type
8-person team
Joined
Jul 2022
Message
136

Doki · Infrastructure migration · 2025

#5

Do your NDAs or service contracts with clients require monitoring by an independent SOC? If you deal with large enterprise clients, they sometimes ask this on vendor assessment forms. If you're not under that kind of contractual pressure, why even keep this offer on the table?

YYasemin Y***Expert
Job title
Sales Manager
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Aug 2022
Message
46
#6

we had a salesperson push us like that too. enabled 2fa closed server ports to the public, warned staff about phishing emails and that was that. 45k lira isn't money to throw away every month.

AAlper P***Member
Job title
System administrator
Sector
Real estate
Organization type
20-person company
Joined
Aug 2024
Message
85
#7

If you're looking for a middle ground, consider these three options: 1) Ask for an 8x5 package covering business hours instead of 24/7; the price usually drops by two-thirds, 2) Request incident response support on an on-demand, hourly retainer basis rather than a flat monthly fee, 3) Keep log retention inside your own cloud, strictly limited to legal compliance minimums.

JJülide V***Member
Job title
Digital marketing specialist
Sector
Chemistry
Organization type
sole proprietorship
Joined
Jul 2023
Message
320
#8

Classic fear-mongering from cybersecurity firms. They act like international hacker syndicates are running coordinated attacks against a 20-person company every night. If your backups are solid and systems are patched, there's no need for this kind of spend.

LLeyla Y***ExpertCommunity member
Joined
May 2025
Message
102
#9

Provided your company is not subject to statutory regulations or licensing mandates, performing a risk assessment in accordance with ISO 27001 standards is sufficient. If the identified risk level is low, strengthening preventive controls is recommended over engaging a full-scale monitoring center.

MMerve T***ExpertCommunity member
Joined
Feb 2024
Message
13
#10

Reject the offer outright. Hook up alerts for suspicious logins and abnormal resource spikes directly from your cloud provider's console to your internal team chat. You'll catch the most critical warnings instantly without spending an extra dime.

CCem I***MemberCommunity member
Joined
Sep 2025
Message
4
#11

This thread is archived.

NNeslihan T***MemberCommunity member
Joined
Nov 2022
Message
226
#12

I agree.

TTuba E***Expert
Job title
Data protection consultant
Joined
Oct 2023
Message
158

Doki · Backup setup · 2024

#13

I've been dealing with this for a long time. Security isn't absolute; it's about making attacks not worth the effort.

Most incidents start with a leaked password, not a vulnerability. If you post the result here, it will help others too.

RReyhan K***Member
Job title
IT manager
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Apr 2023
Message
93
#14

The discussion got scattered, let me summarize. Start with a small trial; don't commit to everything at once.

Hope this helps.

ZZeynep K***Member
Job title
Production Manager
Sector
IT services
Organization type
regional distributor
Joined
Feb 2025
Message
143

Doki · Interface design · 2026

#15

Let me summarize the topic, since several different answers were given. If it's your first time, start small; scaling comes later.

NNecati E***MemberCommunity member
Joined
Jan 2024
Message
3
#16

I'd appreciate it if you shared the outcome. An untested backup is not a backup.

If you have questions, write them; I'll answer as best I can.

OOsman O***MemberCommunity member
Joined
Aug 2022
Message
252
#17

Let me share what happened to me; it might be useful. The harder it is to reverse a decision, the slower you should make it.

ZZerrin C***Member
Job title
Supply chain manager
Sector
Healthcare services
Organization type
workshop
Joined
Jan 2024
Message
10
#18

Following.

KKemal T***MemberCommunity member
Joined
Feb 2023
Message
4
#19

I've been down this road, let me tell you. If 2FA is on, a stolen password alone is useless.

This is my opinion, I'm not claiming it's absolute truth.

RReyhan G***Veteran
Job title
Finance Manager
Sector
Cleaning services
Organization type
boutique agency
Joined
Nov 2024
Message
250
#20

I have an objection here. Hasty decisions become decisions you have to fix six months later.

Good luck with that.

Reply